Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23143

Опубликовано: 05 дек. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zte:otcp_firmware:*:*:*:*:*:*:*:*
Версия до 2.21.40.06 (исключая)
cpe:2.3:h:zte:otcp:-:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00207
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732
CWE-732

Связанные уязвимости

CVSS3: 6.5
github
около 3 лет назад

ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.

EPSS

Процентиль: 43%
0.00207
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-732
CWE-732